Understanding the relationship between SIL and API 670

We often get questions from customers asking whether a system is SIL or API 670-compliant. But these are not interchangeable concepts; they are distinctly different. In fact, strictly speaking, a system cannot be ‘SIL-compliant’ at all.

Two standards, two objectives

SIL (defined by IEC 61508 and for the process the industry, IEC 61511) is a functional safety measure, which determines how reliable safety functions must be. It focuses on the probability that a safety function will fail to perform its required action (ranging from SIL 1 to SIL 4). As the SIL-rating increases, so do the requirements for system design, diagnostics, validation, and testing.

The question SIL asks is, “How reliable must a safety function be?”

The API 670, in contrast, defines the minimum requirements for machinery protection systems used on rotating equipment, including vibration, axial position, temperature and overspeed monitoring. API 670 addresses the architecture of a system, sensors, redundancy, and its voting structure. It outlines several requirements for an overspeed detection system, for instance. One such example is the requirements of a 2oo3 voting structure. Another is that the response time has to be <40 milliseconds. API 670 is a voluntary industrial standard, although end users often make it mandatory in their specifications.

The question API 670 asks is, “How should a machinery protection system be designed and implemented?”

Where do they converge?

SIL and API 670 overlap on several areas:

API 670 prescribes how a protection system needs to be configured and refers to several SIL principles. At the same time, SIL addresses the reliability of the safety function.

Both require the protection function to be independent of the control system. API 670 requires a dedicated ODS and IEC 61511 requires separation between the safety system and the basic process control system (BPCS). Both emphasize diagnostics and periodic proof testing, and both rely on redundancy. API 670 prescribes, while under SIL it is one of the means to reach the required reliability. Finally, both approaches are related to bringing equipment to a safe state when something goes wrong.

To further outline the differences between these two standards, a system can be SIL-compliant, without being API 670-compliant. The opposite is also true. It’s becoming more common, however, for systems to be compliant with both standards.

Different needs, different standards

Ultimately while SIL and API 670 may complement each other, they are not the same. They do not compete, instead answering different questions.

API 670 defines how a machinery protection should be designed and implemented for rotating equipment.

SIL defines how dependable a safety system must be to achieve the required level of risk reduction.

They align most strongly on independence, redundancy and safe shutdown philosophy. Understanding how the two relate helps you select a protection system that meets your machinery protection and functional safety requirements.

Discover our API 670-compliant, SIL-certified overspeed protection »